What security measures does UK data protection law require?
Controllers and processors must have technical and organisational measures appropriate to the risk, taking into account the state of the art, the cost and the nature of the processing, and the law names pseudonymisation, encryption, resilience, restoration after an incident and regular testing. A processor may only act on documented instructions and under a written contract carrying the same duties. The measures must be tested and reviewed, not written once.
Source
- Source
- UK GDPR Articles 28 and 32
- Acts
- Data Protection Act 2018
- Area
- Data protection and online duties
- Checked
- 2026-09-22
Questions
Nästa steg
Vill ni använda registret i eget arbete finns tre vägar in.
Börja med din uppgift
Advokat, tvist
Hitta stöd i avgörande
Sök i vägledande domar, se vad som vunnit laga kraft och följ ändringar i rättsläget.
Bolagsjurist, transaktion
Kartlägg regelverket i affären
Gå från tema till rättsakt och vidare till artikeln som bär kravet.
Compliance
Bedöm risken i en behandling
Riskklassning per rättsområde, med källorna bakom varje poäng.